Re: Allowing a domain user account (specify) to add workstation to Windows 2000 domain (SP4)

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi there,

Thanks for your reply.

1. Should I create Security Global group or Domainlocal Security?

2. I see that I can create a domain user account, add this user account onto
the domain
group that I just created, and in restricted group, add the domain group
onto the restricted
group of GPO, then member = BUILTIN\Administrator

Is that it?

Thanks,
JPTH
"Paul Bergson [MVP-DS]" <pbergson@xxxxxxxxxxxxxxxxx> wrote in message
news:ObwMAQ$BHHA.204@xxxxxxxxxxxxxxxxxxxxxxx
Just use a standard domain user and create a new domain group that is
placed
into the local administrators group on the workstation. If you use
restricted groups you can then modify the group membership to get users
into
and out of the local admin groups with minimal effort.

The gpo settings are at:

computer configuration \ windows settings \ restricted groups

group = your group to be made local admins
member of = BUILTIN\Administrators

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/156780ef-eb36-4433-b3fe-1b1a15c18f6a.mspx

http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_scerestrictgroups.mspx

There is absolutely nothing that has to be done on the client side.



Create the gpo in the ou where the Computers reside (NOT the users), go to
computer configuration/windows settings/security settings/restricted
groups,
right click on restricted groups and select new group (For the local
computers, this group name should be - administrators) and key in the
group
you want auto populated. Select add on the Members of this group and then
add the members you want populated.

To provide users the ability to add workstations Delegate the right to a
group (The same group as in the restricted group used above?).

Create a new security group and provide it the ability to only join
computers to the domain via the "Delegation of Control" wizard. Then join
the user account to this new group.


http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/activedirectory/stepbystep/ctrlwiz.mspx

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"J.H" <jpthsd@xxxxxxxxxxx> wrote in message
news:OWtAcS1BHHA.4740@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
Previously, we removed the right to add workstation to Windows 2000
domain.
However, now we are trying to expand our IT dept, so hiring more IT Help
Desk Support,
We'd like to allow IT Help Desk Support technician to: (without giving
the
account
domain_admin right)

a. login onto the workstation with administrator privilege (domain
logon)
b. having ability to add any workstation onto the Windows 2000 domain

Any one can suggest the hint, please let us know, we appreciate your
help

Regards,
JPTH






.



Relevant Pages

  • Re: Filesharing Problems
    ... What security programs are running? ... Now any computer on the network can browse to any other computer on ... put all computers in the same Workgroup. ... Select a user account to automatically log on by ...
    (microsoft.public.windows.vista.networking_sharing)
  • Re: Need help closing security holes in my Windows XP home system!
    ... really, stop using the win xp user account with admin, that makes it ... Look you ignorant moron, I've been using computers for nearly 25 years, ... and not security issues, which goes against the entire world's opinion ... Admin rights, ...
    (comp.security.firewalls)
  • Re: Need help closing security holes in my Windows XP home system!
    ... > really, stop using the win xp user account with admin, that makes it ... > Look you ignorant moron, I've been using computers for nearly 25 years, ... So it's more than a little insulting when you write ... > and not security issues, which goes against the entire world's opinion ...
    (comp.security.firewalls)
  • Re: Allowing a domain user account (specify) to add workstation to Windows 2000 domain (SP4)
    ... Please no e-mails, any questions should be posted in the NewsGroup ... I see that I can create a domain user account, ... Create the gpo in the ou where the Computers reside, ...
    (microsoft.public.win2000.active_directory)
  • Re: Restrictions on users?
    ... It sounds like you want to start using some security ... You can see all of the local policies on each ... >user account to have restrictions on not to install any ... >> If you want to restrict them to several computers, ...
    (microsoft.public.win2000.security)